- A vulnerability in a March 2021 Coldcard firmware release enabled attackers to drain bitcoin from thousands of wallets by reproducing keys generated with weak software-based randomness.
- Three distinct attack waves have swept 1,367 bitcoin (nearly $89 million) from 4,585 addresses, with the latest wave targeting smaller balances and using more complex, harder-to-trace transaction patterns.
- Galaxy Research believes each wave is the work of a single operator but cannot determine if the same attacker is behind all three due to blockchain limitations.
- The flaw routed seed generation to a predictable software randomizer instead of the chip's hardware one, leaving a bounded set of possible keys that can be reproduced offline.